Hi Yokota, On 04/08/26 10:31 PM, yokota wrote: > Hello Debian LTS team, > > Thank you for update Debian calibre for bullseye. > I was maintain calibre for sid. > > In CVE-2026-25636 fix in calibre 6.13.0+repack-2+deb12u6 has some bug > that describes Debian bug 1143484. > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143484
Thanks. So just to be clear, LTS team only uploaded to bullseye suite (5.12.0+dfsg-1+deb11u5) and with a cursory read of the above bug report, I believe bullseye version is _safe_ given we backported function "is_existing_subpath". But I have not tested with an actual epub file. Let me see if I can find a epub file as described in the bug report. If you have that PoC, please do share. > I make fixups for the bug. > Please update calibre for bookworm LTS. > > You can examine and download patches from GitHub: > https://github.com/debian-calibre/calibre/compare/debian/6.13.0+repack-2+deb12u9...bookworm-update Thank you. I will do a release with your patches. > FYI: > I make fixups for trixie and send bug report for release team. > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143581 Thank you. --abhijith
